Zenith Bank Plc Data Breach

Alleged

Ransomware claim involving Zenith Bank Plc

Published: Jul 26, 2026
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Zenith Bank Plc
Industry
Financial Services
Date of Incident
Jul 26, 2026

Executive Summary

Zenith Bank Plc, a prominent financial services organization based in Nigeria, was identified on the leak portal of ExfilSquad, an extortion-focused threat actor, on July 26, 2026. The discovery was made via SOCRadar’s Dark Web Monitoring service, which continuously scans claims on ransomware and extortion sites. While the organization’s sector and country of operation are noted, the provided data offers no further specifics about the institution. Being listed by ExfilSquad places Zenith Bank Plc among fourteen entities claimed by the group within the preceding 60 days. Its classification within the financial services sector aligns with the group’s recent targeting patterns, as this industry has been affected by ExfilSquad more than once in the same timeframe. Over the 60 days leading up to this listing, ExfilSquad publicly claimed 13 additional victims, bringing their total to 14 within this period. The group’s victims are predominantly in the Government & Defense sector (four entities), followed by Technology (three) and Financial Services (two, including Zenith Bank Plc). Geographically, the majority of ExfilSquad’s claimed victims are located in the United States (nine), with a smaller number in the United Kingdom (three) and one in Nigeria. Notable entities within this recent activity window include Allstate and Microsoft in the United States, and the UK Department for Education and the Police National Legal Database in the United Kingdom. A significant observation is that all fourteen claims, including Zenith Bank Plc’s, were posted on July 26, 2026, within a single 24-hour span. This bulk-posting behavior suggests caution in independently verifying each claim. Zenith Bank Plc also stands out as ExfilSquad’s sole Nigerian target in the reported period.

Technical Analysis

A review of SOCRadar’s stealer-log telemetry for the domain zenithbank.com yielded no records within the queried dataset. Furthermore, no specific infostealer analysis related to this listing was generated during the reporting period. It is important to note that infostealer-driven initial access is not the primary tactic associated with threat actors like ExfilSquad. Such data-extortion groups typically rely on methods such as social engineering, callback phishing, or widespread credential abuse targeting a single SaaS platform, rather than solely on commodity stealer logs. Consequently, the absence of stealer-log records does not offer conclusive evidence regarding the entry point of this incident. The null result should be interpreted as a lack of available data, rather than proof for or against any specific access methodology. This finding underscores that the lack of observed evidence does not equate to evidence of absence, meaning a compromise cannot be ruled out based solely on this telemetry.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.